Meuralmcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Meuralmcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Small LAN-first daemon, REST API, and MCP server for keeping Meural Canvas previews loaded.
and portrait devices, sets hold durations, and syncs configured cloud device IDs.
This project builds on public Meural local-control work from the community:
Home Assistant forum, demonstrated that Meural Canvas devices expose both a cloud API and a local interface suitable for Home Assistant control.
documents the built-in browser-accessible /remote controller on the same LAN.
documented the practical issue with transient preview/postcard display and the more reliable single-playlist/gallery pattern.
Most users should run cloud init first. It is the step that discovers your frames, writes the starter config, changes Meural cloud timeout settings, and assigns the neutral blank gallery used by the local preview manager.
Cloud init changes these Meural cloud values:
imageDuration=86400, previewDuration=86400, and overlayDuration=120on discovered devices.
Cloud init does not delete your existing Meural images or galleries, but it can change which gallery is assigned to each discovered device. Review the generated config.json after init and edit device names, IPs, orientations, or enabled flags before starting the daemon.
python -m venv .venv
. .venv/bin/activate
pip install -e .
meural-mcp --storage-dir ~/.config/meural-mcp init-cloud \
--username "$MEURAL_USERNAME" \
--password "$MEURAL_PASSWORD"Package dependencies are declared in pyproject.toml; pip install -e . installs the CLI plus bounded runtime dependencies for FastAPI, Uvicorn, Requests, and MCP.
llms.txt is included as a concise map for coding agents and documentation ingestion. AGENTS.md contains contributor guardrails for keeping this repo public-safe.
If you do not want cloud init, init-local can create an empty generic config:
meural-mcp --storage-dir ~/.config/meural-mcp init-local --api-token "change-me"With init-local, you must manually fill in device names, cloud IDs, LAN IPs, orientations, and enabled flags in ~/.config/meural-mcp/config.json. It also does not set timeout values or blank galleries in Meural cloud.
Run the API:
meural-mcp --storage-dir ~/.config/meural-mcp serve --host 127.0.0.1 --port 8733Keep the REST API bound to localhost where possible. If you want to expose it to other machines, put nginx or Caddy in front of it and terminate HTTPS there rather than binding the API directly to the LAN as plain HTTP.
Check summary status:
curl http://127.0.0.1:8733/status \
-H "Authorization: Bearer change-me"Run the daemon:
meural-mcp --storage-dir ~/.config/meural-mcp daemonSample service and reverse-proxy files are provided in examples/:
examples/systemd/meural-mcp-daemon.serviceexamples/systemd/meural-mcp-api.serviceexamples/systemd/meural-mcp-user.serviceexamples/systemd/meural-mcp-api-user.serviceexamples/reverse-proxy/Caddyfileexamples/reverse-proxy/nginx.confinit-cloud is a one-shot CLI setup command. Run it manually so you can see and approve the cloud changes. The daemon and API are separate long-running processes: the daemon keeps previews loaded, and the API serves local status and image writes. In the system service examples, both long-running services use /var/lib/meural-mcp for config/state and expect the project installed at /opt/meural-mcp/.venv/bin/meural-mcp.
For a system install:
sudo useradd --system --home /var/lib/meural-mcp --create-home --shell /usr/sbin/nologin meural-mcp
sudo install -d -o meural-mcp -g meural-mcp /var/lib/meural-mcp
sudo cp examples/systemd/meural-mcp-*.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now meural-mcp-daemon.service meural-mcp-api.serviceFor a user install:
mkdir -p ~/.config/systemd/user
cp examples/systemd/meural-mcp-user.service ~/.config/systemd/user/meural-mcp.service
cp examples/systemd/meural-mcp-api-user.service ~/.config/systemd/user/meural-mcp-api.service
systemctl --user daemon-reload
systemctl --user enable --now meural-mcp.service meural-mcp-api.serviceThe user service samples expect meural-mcp at ~/.local/bin/meural-mcp. Adjust ExecStart if you installed into a project virtual environment instead.
For LAN access, keep meural-mcp-api.service on 127.0.0.1:8733 and expose it through HTTPS with Caddy or nginx. The shared token is still required by MeuralMCP, but TLS should protect the token in transit.
The API service also exposes a remote streamable-HTTP MCP endpoint at /mcp/. When the API is behind HTTPS, coding agents that support remote MCP should connect directly to that URL with the same bearer token used by the REST API. Clients do not need the MeuralMCP package installed just to use this hosted MCP endpoint.
Set MEURAL_MCP_ALLOWED_HOSTS on the API service to the HTTPS hostnames clients will use for remote MCP, such as meural-mcp.example.test or meural-mcp.example.test:443. This keeps the MCP transport's DNS-rebinding protection enabled while allowing your reverse-proxy hostname.
Example remote MCP URL:
https://meural-mcp.example.test/mcp/Run the stdio MCP adapter only for coding agents that do not support remote MCP:
meural-mcp --storage-dir ~/.config/meural-mcp mcp --transport stdioIf this compatibility adapter runs on your workstation while the daemon/API run on another host, point it at the remote API instead. In this mode, set_device_image reads the image path from the workstation and uploads the bytes to MeuralMCP:
export MEURAL_MCP_API_URL="https://meural-mcp.example.test"
export MEURAL_MCP_API_TOKEN="..."
export MEURAL_MCP_API_VERIFY_TLS=false # only for self-signed lab certs
meural-mcp mcp --transport stdioMCP tools include:
list_devicesget_device_statusget_device_imageset_device_imageset_device_image_datalist_devices and get_device_status return the configured device name, display name, cloud ID, LAN IP, orientation, enabled flag, reachability, current assigned image, and the last recorded state for each device.
For hosted remote MCP, prefer set_device_image_data, which accepts base64 image bytes plus a filename. set_device_image accepts a path that is local to the machine running the MCP server, so it is mainly useful for stdio adapters or server-local files.
Both image-writing tools store the image only after validating orientation and successfully loading the preview to the device. They return a failed result if the image cannot be parsed/thumbnailed, the orientation is wrong, the device is unknown, the file is missing, or the preview write fails.
Upload an image:
curl -X PUT http://127.0.0.1:8733/devices/canvas-1/image \
-H "Authorization: Bearer change-me" \
-H "Content-Type: image/jpeg" \
--data-binary @image.jpgCloud init requires a Meural username/password.
meural-mcp --storage-dir ~/.config/meural-mcp init-cloud \
--username "$MEURAL_USERNAME" \
--password "$MEURAL_PASSWORD"On a Linux host with user systemd available, add --install-systemd to write, enable, and start meural-mcp.service. Interactive runs prompt for this unless --no-systemd-prompt is supplied.
init-cloud:
config.json.config.json, and prints it so you can save it for REST/MCP clients.config.json already exists, writes a timestamped backup first.imageDuration=86400, previewDuration=86400, overlayDuration=120.After init, review and edit config.json if you need to adjust device names, cloud IDs, LAN IPs, orientations, or enabled flags before running the daemon.
Polling is not elegant, but it is deliberate. Meural frames can lose the loaded preview after sleep, boot, or other internal resets, so the daemon checks periodically and reloads the assigned preview when needed.
The blank image is a holding pattern. It keeps the device on a single neutral gallery by default, which makes the transition to locally managed previews a little less awkward than leaving whatever cloud playlist happened to be active.
Probably, but this still needs testing. Once cloud init has discovered devices, set the timeout values, and assigned the blank galleries, users may be able to firewall the Meural devices from the internet so future Meural cloud changes cannot alter or disturb them.
A better solution likely needs hardware-level investigation. A community teardown/hacking post describes a Meural RK3288 board and locating G, R, and T test pads for ground, RX, and TX serial console access. Someone needs to open a device, attach to those serial pins, and see whether there is a cleaner local-control path than periodic preview reloads.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.